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Certificate ::= SEQUENCE 
tbsCertif icate 
signatureAlgorithm 
signature 



TBSCertif icate, 
Algorithmldentif ier , 
BIT STRING } 



TBSCertif icate 



SEQUENCE { 



[0] 



version 
serialNumber 
signature 
issuer 
validity 
subject 

subj ectPublicKeylnf o 
issuerUniquelD [1] 
subjectUniquelD [2] 
extensions [3] 



Version DEFAULT vl, 

Cert if icateSerialNumber , 

Algorithmldentif ier , 

Name, 

Validity, 

Name, 

Subj ectPublicKeylnf o, 
IMPLICIT Uniqueldentif ier OPTIONAL, 
IMPLICIT Uniqueldentif ier OPTIONAL, 
Extensions OPTIONAL } 



Version 



INTEGER { vl(0), v2 (1) , v3(2) } 



Cert if icateSerialNumber 

Validity SEQUENCE { 

notBef ore 
notAf ter 

Time : := CHOICE { 
utcTime 
generalTime 

Uniqueldentif ier : ; 

Subj ectPubl icKeylnf o : 
algorithm 
subj ectPublicKey 



:= INTEGER 



Time, 
Time } 



UTCTime, 

General izedTime } 



BIT STRING 



SEQUENCE { 

Algorithmldentif ier , 
BIT STRING } 



Extensions : : = 

Extension : : = 
extnID 
critical 
extnValue 



SEQUENCE SIZE (1..MAX) OF Extension 
SEQUENCE { 

OBJECT IDENTIFIER, 
BOOLEAN DEFAULT FALSE, 
OCTET STRING } 
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CertificateList ::= SEQUENCE { 

tbsCertList TBSCertList, 

signatureAlgorithm Algorithmldentifier, 

signatureValue BIT STRING } 

TBSCertList ::= SEQUENCE { 

version Version OPTIONAL, 

signature Algorithmldentifier, 

issuer Name, 

thisUpdate Time, 

nextUpdate Time OPTIONAL, 

revokedCertificates SEQUENCE OF SEQUENCE { 

userCertificate CertificateSerialNumber, 

revocationDate Time, 

crIEntryExtensions Extensions OPTIONAL 
} OPTIONAL, 

crIExtensions [0] EXPLICIT Extensions OPTIONAL 
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certFingerprint ::= SEQUENCE OF SEQUENCE { 
algorithm Algorithmldentifier, 
fingerprint octet string 

} 
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702 
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704 
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706 
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708 
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COMPUTE CERTIFICATE FINGERPRINT 


712 
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AUTHENTICATE CLIENT 
710 
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